CVE-2023-0164: Orangescrum

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.

Affected products

Published 2023-01-18. Last modified 2026-06-17.